Thousands of organizations have a new, unexpected ’employee’ onboard – and it could be their single biggest security risk
- Report warns hackers are exploiting browser agents which don’t know how to spot fake URLs
- A Browser AI Agent gave full Google Drive access to a malicious app without hesitation
- SquareX says AI agents are more vulnerable than humans to even basic cyberattacks
A dramatic shift in enterprise security has emerged with the adoption of Browser AI Agents, an automated tool that interacts with the web on behalf of users – however these agents have now become a major blind spot in cybersecurity defenses.
New research from SquareX has claimed browser AI Agents are more likely to fall prey to cyberattacks than employees – challenging the long-standing belief that human error is the weakest link.
Unlike staff who undergo regular cybersecurity training, agents cannot recognize “suspicious URLs, excessive permission requests, or unusual website designs,” the company says.
A new weakest link emerges in enterprise cybersecurity
“The arrival of Browser AI Agents have dethroned employees as the weakest link within organizations,” said Vivek Ramachandran, CEO of SquareX.
These agents are capable of mimicking user behavior to perform tasks such as booking flights, scheduling meetings, or replying to emails – however, their fundamental weakness lies in their complete lack of security intuition.
Their responses are entirely task-driven and devoid of the critical thinking needed to assess risk.
In a notable demonstration, SquareX used the open source Browser Use framework to instruct an AI agent to register for a file-sharing tool.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The agent instead granted a malicious application access to a user’s email account, despite “irrelevant permissions, unfamiliar brands, suspicious URLs” that would have stopped a human.
In another case, an agent was tricked into entering login credentials on a phishing site, following a routine Salesforce login instruction.
Part of the danger stems from the way Browser AI Agents operate, as they run with the same privileges as the user, which makes their actions indistinguishable from legitimate behavior.
“Optimistically, these agents have the security awareness of an average employee, making them vulnerable to even the most basic attacks, let alone bleeding-edge ones,” SquareX said.
“Critically, these Browser AI Agents are running on behalf of the user, with the same privilege level to access enterprise resources.”
Once an agent is compromised, attackers gain undetected access to internal systems, with all the permissions of a trusted employee.
The current crop of security solutions, ranging from the best endpoint protection to the best ZTNA solution, does not sufficiently account for these agents.
Even the best FWAAS deployments may struggle to flag actions that seem legitimate but originate from a compromised AI.
“Until the day browsers develop native guardrails for Browser AI Agents, enterprises must incorporate browser-native solutions like Browser Detection and Response to prevent these agents from being tricked into performing malicious tasks,” the researchers note.
However, the broader message remains urgent: AI agents need not only smart engineering but smarter oversight.
You might also like
Report warns hackers are exploiting browser agents which don’t know how to spot fake URLs A Browser AI Agent gave full Google Drive access to a malicious app without hesitation SquareX says AI agents are more vulnerable than humans to even basic cyberattacks A dramatic shift in enterprise security has…
Recent Posts
- Tesla teases Cybercab with a built-in Starlink V5 antenna
- The wireless headset that gets hot-swappable batteries right
- Halliday’s New Smart Glasses Skip the Camera
- Geekom AX8 Max vs Geekom A9 Max: Which mini PC deal should you buy from $619?
- 5 questions to ask before choosing a robot lawn mower, according to a lawnbot exec
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023